Rogue Agent Watch › Records › dprk-it-worker-fraud-claude
North Korean IT-worker remote-employment fraud using Claude
Disclosed · added to the index · last updated
Grades
- Verification status
- Confirmed — Confirmed by a first-party disclosure or multiple independent credible sources.
- Sourcing confidence
- Primary — Backed by primary sourcing — first-party disclosure, vendor incident report, government advisory, or court documents.
- AI role
- Significant — AI materially enabled or accelerated the operation, but was one of several important components.
- Severity
- High — Significant confirmed harm to one or more organizations.
Summary
In its August 2025 Threat Intelligence Report, Anthropic disclosed that North Korean operatives systematically used Claude to obtain and hold fraudulent remote engineering jobs at technology companies as a means of evading sanctions and funding the regime. Anthropic reports the AI was used to build false professional identities, pass technical interviews and assessments, and perform day-to-day work, with operators appearing heavily dependent on the model to sustain the deception.
Impact as stated
Fraudulent employment at technology companies to evade sanctions and generate revenue for the DPRK regime; Anthropic notes such IT-worker schemes are reported to generate hundreds of millions of dollars annually for weapons programmes.
Facts as stated by sources
- Actor
- North Korean operatives (DPRK IT workers) (Nation-state)
- Category
- Infrastructure abuse / supply chain
- Models named
- Claude
- Model families
- Claude (Anthropic)
- Agentic autonomy level
- Tool-assisted
- Guardrail bypass
- Legitimate tool abuse
- Attack lifecycle phases
- Resource development, Deception / social engineering
- Target sectors
- Technology
- Target countries
- US
- Organisations affected
- not stated
- Records exfiltrated
- not stated
Framework mappings
None recorded upstream.
Map points
- origin: North Korea (state sponsor, per Anthropic) (illustrative, country-level centroid; sponsor attribution, per Anthropic; KP)
- target: United States (victim employers, per Anthropic) (illustrative, country-level centroid; victim location, per Anthropic; US)
Related records
- GTG-2002 'vibe hacking' AI-driven data-extortion operation
- GTG-5004 AI-assisted ransomware-as-a-service operation
Sources (2)
- Detecting and countering misuse of AI: August 2025
Anthropic · First-party disclosure · · archived copy - Threat Intelligence Report: August 2025
Anthropic · Vendor report · · archived copy
Revisions
- — Map point basis corrected: the origin point was labelled "operator origin" but the cited sources state regime affiliation and funding, not where the operators were located. Re-typed as sponsor-attribution. Added a US victim-location point and targets.countries from the same source.
Cite this record
Agentic Attack Index (MLSecOpsHub), dataset v0.3.0, record "dprk-it-worker-fraud-claude". https://raw.githubusercontent.com/MLSecOpsHub/agentic-attack-index/main/dist/incidents/dprk-it-worker-fraud-claude.json — CC BY-SA 4.0.